HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedSupply Chain (3P Vendor)IDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
DocketWise
bd_40e1c71041a9a978 · schema v1 · pii pii-v1
Full breach record for DocketWise →DocketWise, a case management platform for immigration attorneys, issued a supplemental notice to the New Hampshire Attorney General regarding a data security incident. In October 2025, unauthorized actors used valid credentials to access a third-party partner instance, cloning repositories containing customer data. The incident affected 11 New Hampshire residents, exposing names, addresses, SSNs, and government IDs. DocketWise engaged forensic experts, notified the FBI, and provided 24 months of credit monitoring.
This filing is one of 9 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (8) · sorted by filing gap
- bd_b7206884fd165144California State AGfiled 2026-05-01Verified by operator
- bd_1f933422ef9106ceMaine State AGfiled 2026-05-22(21d gap)Verified
- bd_14c2b0dfc72d503eWashington State AGfiled 2026-04-03(28d gap)Candidate
- bd_19d49447e198e5e8New Hampshire State AGfiled 2026-04-03(28d gap)Verified
Show 4 more filings ↓Show fewer ↑up to 28d gap
- bd_270698bf44ac9aafMaine State AGfiled 2026-04-03(28d gap)Verified
- bd_db21719c17d2f149Vermont State AGfiled 2026-04-03(28d gap)Verified
- bd_e285f2bea7e3adc5Indiana State AGfiled 2026-04-03(28d gap)Verified by operator
- bd_f56df3950ca029eeCalifornia State AGfiled 2026-04-03(28d gap)Verified by operator
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/docketwise-20260501.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 1, 2026
- Raw hash
- c6faa4e5163b6eaed25e4669471e6c51a5f31ccc3f8309e5d71aa06f1fcd1c9a
Reporting entity
- Name
- GOODWIN PROCTER LLPnorm: goodwin procter
- Domain
- goodwinlaw.com
Victim entity
- Name
- DocketWisenorm: docketwise
- Domain
- app.docketwise.com
Incident
- Discovered
- Oct 1, 2025
- Materiality determined
- —
- Notification sent
- May 1, 2026
- Affected individuals
- 11
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1195 Supply Chain Compromise
- Threat actor
- External
- Regulator citations
- Notified New Hampshire Attorney General
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 30 weeks(212 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.